CVE-2026-42434Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions 2026.4.5 before 2026.4.10 contain a sandbox escape vulnerability allowing sandboxed agents to override exec routing by specifying host=node. Attackers can bypass sandbox boundaries and route execution to remote nodes instead of intended sandbox paths.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-05); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-05: 2Mentions · 2026-05-06: 1Patch / Workaround · 2026-05-06: 1Technical Details · 2026-05-05: 2Technical Details · 2026-05-06: 105-0505-06
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-052
Disclosure2
2026-05-061
Patch1
Full discourse3 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Patch

    🚨 7 ثغرات خطيرة في OpenClaw! ⚠️ الثغرتين الأخطر ممكن تستغل بدون صلاحيات (Unauthenticated): (CVE-2026-43534) | تقييم 9.3 تخلي بيانات خارجية (External hook metadata) تعامل كأنها أوامر داخلية موثوقة للنظام و ثد تنتقل إلى سياق أعلى ثقة داخل الـ agent بدون تدخل من المستخدم. (CVE-2026-43566) | تقييم 9.1 المخترق يرسل (Webhook) من مصدر غير موثوق، ويتجاوز نظام الصلاحيات ليتنفذ الأمر كأنه من مالك النظام نفسه! ⚙️ الخمس ثغرات الباقية تحتاج صلاحيات منخفضة للاستغلال وكلها بتقييم 8.8: (CVE-2026-43571): إضافة خبيثة تنزل مكان الإضافة الرسمية بسبب خلل في ترتيب البحث وتتجاوز أدوات التحقق. (CVE-2026-43569): إضافة غير موثوقة تتفعل تلقائياً وقت الإعداد الأولي (Onboarding) بدون إذن المستخدم. (CVE-2026-43530): استخدام أدوات مجمعة مثل (busybox) يخلي المخترق يموّه الأوامر. النظام يوافق على أمر آمن ظاهرياً لكن اللي يتنفذ فعلياً أمر خبيث. (CVE-2026-42435): حقن متغيرات حساسة في الشل (مثل SHELLOPTS) على مستوى (argv) وتجاوز الفحص قبل التنفيذ. (CVE-2026-42434): هروب الوكيل من الـ Sandbox. 🛡️ حدّث فوراً لإصدار (2026.4.14).

    Post summary

    The post announces seven CVEs in OpenClaw, explains technical abuse paths, and urges users to patch to version 2026.4.14.

    03016102.5K
    49.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42434 OpenClaw versions 2026.4.5 before 2026.4.10 contain a sandbox escape vulnerability allowing sandboxed agents to override exec routing by specifying host=node. Attacke… https://www.cve.org/CVERecord?id=CVE-2026-42434

    Post summary

    The post references CVE-2026-42434, noting a sandbox escape vulnerability affecting OpenClaw versions 2026.4.5–2026.4.9, but provides no PoC, exploit, or patch information.

    00010156
    57.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42434 OpenClaw versions 2026.4.5 before 2026.4.10 contain a sandbox escape vulnerability allowing sandboxed agents to override exec routing by specifying host=node. Attacke… https://www.cve.org/CVERecord?id=CVE-2026-42434 ----- Traducción: CVE-2026-42434 Ope… http://infoflow.cloud`

    Post summary

    The post announces a sandbox escape vulnerability (CVE‑2026‑42434) in OpenClaw versions 2026.4.5 to 2026.4.10, where sandboxed agents can bypass execution restrictions by specifying host=node.

    0000043
    75 followersView on X

Explore more